S 3404 United States Senate · 119th Congress

Satellite Cybersecurity Act of 2025

The Satellite Cybersecurity Act of 2025 requires the Comptroller General to study federal efforts supporting cybersecurity for commercial satellite systems and report findings to Congress within two years. It mandates the Department of Commerce to establish a public online clearinghouse containing voluntary cybersecurity resources, including tailored guidance for small businesses. The clearinghouse will consolidate recommendations covering risks like hacking, jamming, supply chain vulnerabilities, and foreign ownership threats to satellite systems. This bill directly affects commercial satellite operators (non-Federal entities with licenses), federal agencies using satellite services, and small businesses developing satellite technology.
Sub-Topics: Cybersecurity
Bill status passed 3 of 5 stages cleared
Introduction
Dec 2025
Committee Review
Sep 2026
Senate Passage
Sep 2026
House Passage
President
Introduced Dec 9, 2025 Last action Sep 24, 2026
Maddy AI version diff · 1 comparison

What changed between versions

Introduced in Senate → Engrossed in Senate · 8 edits · Sep 23, 2026
MODERATE
The engrossed version significantly narrows the bill's scope from a framework that could imply regulatory authority to one explicitly limited to coordination, information sharing, and voluntary best practices. The FCC is removed as a coordinating entity throughout, replaced by OSTP and NIST. New rules of construction explicitly prohibit rulemaking, enforcement actions, or license conditions, and protect existing CFIUS authorities. The GAO report is now barred from recommending new or changed authorities for Federal agencies.
Scope change
The bill's scope was substantially narrowed. It shifted from language that could support regulatory or enforcement actions ('address and improve cybersecurity') to explicitly voluntary, coordination-focused language. New rules of construction prohibit rulemaking, enforcement, and license conditions, and protect CFIUS authorities. The clearinghouse is now defined as a public/voluntary resource repository rather than a potential regulatory tool.
SCOPE

The strategy in section 5 was redefined from 'address and improve the cybersecurity of commercial satellite systems' to 'support coordination, information sharing, and voluntary best practices among Federal agencies and private sector stakeholders.' This reframes the entire bill as a non-regulatory coordination effort.

Two new rules of construction were added: (3) nothing authorizes rulemaking or regulatory requirements including enforcement actions or conditions on licenses/permits for commercial satellite systems, and (4) nothing modifies or expands existing authorities of CFIUS or the Committee for Assessment of Foreign Participation in US Telecommunications Services Sector.

The clearinghouse coordination was changed from the Chair of the FCC and the Director of CISA to the Secretary of Homeland Security. A purpose clause was added specifying it serves as a repository for 'publicly available resources, guidance, frameworks, voluntary recommendations, and tools.'

The Office of Science and Technology Policy was added as a consultation entity in section 3(c) and as a coordinating party for the strategy in section 5. The Director of NIST was added to implementation coordination in section 4(d). The FCC was removed from all coordination roles.

REQUIREMENT

The GAO report in section 3(b) now has a new paragraph (2) stating it 'shall not include recommendations described in paragraph (1)(H) for new or changing authorities or regulations for Federal agencies,' explicitly limiting what the study can recommend.

A new clearinghouse requirement (F) was added: it may not contain sensitive security or proprietary information without an established gateway to limit access to approved users.

Clearinghouse content item (K) was limited to recommendations 'only for the purpose described in subsection (b)(1),' restricting the scope of what can be included.

TECHNICAL

The name of the Critical Infrastructure Protection Act was corrected to 'Critical Infrastructures Protection Act' (added an 's'), and 'Department of Commerce' was changed to lowercase 'department of commerce' in a section heading.

Floor votes

How they voted

This bill passed the Senate. No roll call record of that vote is available.
Full legislative history

Actions timeline

Total actions
10
Key actions
4
Committee
3
Sep 23, 2026
Upper · Passed
Passed Senate with an amendment by Unanimous Consent. (consideration: CR S4956-4958; text of amendment in the nature of a substitute: CR S4957-4958)
upper
Sep 23, 2026
Upper · Passed
Passed/agreed to in Senate: Passed Senate with an amendment by Unanimous Consent. (consideration: CR S4956-4958; text of amendment in the nature of a substitute: CR S4957-4958)
upper
Sep 14, 2026
Upper · Passed
Committee on Commerce, Science, and Transportation. Reported by Senator Cruz with an amendment in the nature of a substitute. With written report No. 119-141.
upper
Apr 14, 2026
Upper · Passed
Committee on Commerce, Science, and Transportation. Ordered to be reported with an amendment in the nature of a substitute favorably.
upper
Dec 9, 2025
Committee
Read twice and referred to the Committee on Commerce, Science, and Transportation.
upper
Dec 9, 2025
Introduced
Introduced in Senate
upper
1 primary · 1 co-sponsor

Sponsors